How Likhtam handles your business data — in plain terms.
Last updated: 30 September 2026
Likhtam ("the app") is developed and operated by TechShah("we", "us"), a company based in Delhi, India. Likhtam is an accounting, GST billing, inventory and loan-tracking application. This policy explains what data the app collects, how it's stored, when it leaves your device, and the choices you have. It applies to the Likhtam mobile and web apps and this website, and is written to meet the obligations of India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, "DPDP"), as well as general data-protection expectations for users of Likhtam outside India.
To run your books, Likhtam works with:
We do not collect data we don't need to run the app. There is no advertising SDK in Likhtam, and we do not sell business or personal data.
When you create a Likhtam account, you're asked to actively tick a checkbox confirming you agree to these terms and this privacy policy, and consent to your personal data (name, email, phone) being processed to create and operate your account — account creation is blocked until you do. You can withdraw consent at any time by deleting your account (Profile > Danger Zone > Delete My Account) or company (Company Settings > Danger Zone > Delete Company) directly inside the app, or via https://likhtam.com/delete-account, though withdrawing consent for data already needed to complete an in-progress transaction or legal obligation may not be immediate.
By default, Likhtam is offline-first: your ledgers, invoices, inventory and reports are stored locally on your device. On the Free plan, your data stays on that device unless you back it up or export it yourself. Your account details (name, email, phone) and activity log are always stored on our servers so you can sign in.
Trial and Pro plans can turn on real-time cloud sync so the same books are available across your devices. When enabled, your business data is stored on our backend infrastructure (via Supabase) in an encrypted database, accessible only to your account and any team members you explicitly invite. Turning cloud sync off stops new data from syncing; previously synced data can be deleted on request.
Android subscriptions go through Google Play Billing under Google's standard terms. Web subscription payments in India go through Razorpay under its PCI-DSS compliant systems. Neither Google Play Billing nor Razorpay gives us your card, bank, or UPI details. Likhtam only receives confirmation that a payment succeeded, along with a transaction reference for plan activation and receipt generation.
This marketing website does not use advertising cookies, tracking pixels, or third-party analytics scripts. If that changes in the future — for example, to add privacy-respecting analytics — this section will be updated first to say what's added and why.
We share data only where it's needed to run the service (as sub-processors):
We do not share your business data with advertisers or data brokers.
Our primary database is in India (Mumbai). For users outside India, your data is transferred to and processed in India. When your data is transferred to India, we protect it with the same safeguards described in this policy.
Locally stored data stays on your device until you delete the app, reset app storage, or delete your company/account. Cloud-synced data is retained while your account is active. Users can delete their account (Profile > Danger Zone > Delete My Account) or company (Company Settings > Danger Zone > Delete Company) directly inside the app, or via https://likhtam.com/delete-account or by writing to support@likhtam.com.
Statutory tax retention notice: Please be aware that tax law may require businesses to keep invoices, ledgers, vouchers, and books for prescribed statutory periods (India 6–8 years under GST, Income Tax and the Companies Act; Gulf region 5–7 years; UK, Australia, and Singapore 5 years). We strongly recommend you export all reports and accounting statements before deleting your company or account.
All cloud-synced data is encrypted in transit using industry-standard Transport Layer Security (TLS) and stored on secure cloud database infrastructure. Day-to-day transaction records, invoices, and books remain stored locally on your device for offline use. Access to production systems is strictly restricted to authorized personnel. While no electronic transmission or storage method is 100% secure, we implement technical and organizational security measures to safeguard your financial records and personal information.
As a Data Principal under DPDP (or under the equivalent law where you're registered), you have the right to:
To exercise any of these rights, contact us at support@likhtam.com. If you're not satisfied with our response, you may escalate a DPDP complaint to India's Data Protection Board.
Our website and app may link out to third-party sites (like the Play Store, or Razorpay's checkout page). We're not responsible for the privacy practices of those sites — check their own policies before sharing information with them.
Likhtam is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
If this policy changes materially, we'll update the "Last updated" date above and, for significant changes, notify account holders by email.
Questions about this policy or your data: support@likhtam.com or +91 88260 90432. TechShah is based in Delhi, India.
In accordance with the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and rules made thereunder, the Grievance Officer for privacy-related complaints can be reached at the same address. We aim to acknowledge privacy complaints within 48 hours and resolve them within 30 days.
If we become aware of a personal data breach affecting your account, we'll notify you and the Data Protection Board without undue delay, describing what happened, what data was involved, and what you can do — consistent with DPDP's breach-notification requirements.